Le dim. 3 mars 2024 à 15:10, Yoann CONGAL <[email protected]> a écrit :

>
>
> Le dim. 3 mars 2024 à 14:18, Peter Marko via lists.yoctoproject.org
> <[email protected]> a écrit :
>
>> I already mentioned this last week.
>> https://lists.openembedded.org/g/openembedded-core/message/196199
>>
>> I think that partial NVD DB update is not working properly as things
>> which were corrected by NVD are still showing up in patchmetrics but not in
>> email reports.
>>
>
> The yocto-metrics repo shows that CVE-2022-3563 has been "Unpatched" since
> its creation 31/10/2023.
> +1 on the "partial NVD DB update is not working properly" hyptohesis
>
> Looking into this, I've started to look at the NVD API: IIUC, a partial
> update is done by requesting every CVE that have a lastModified field
> after our last update.
>
> But from the NVD API doc:
> https://nvd.nist.gov/developers/vulnerabilities#cves-lastModDates
>
>> A CVE's lastModified *does* *not* change when any of the follow actions
>> occur:
>> [...]
>> The NVD modifies a CPE record previously associated with the CVE record
>
>
> If I read that correctly, this means that CVEs CPE updated by the NVD
> (which is what we frequently request to the NVD) would not have their 
> lastModified
> field updated and then, missed by the partial update. Sounds like a bug, no?
>

Hmmm, maybe not so simple: Take CVE-2023-3180 for exemple:
* https://nvd.nist.gov/vuln/detail/CVE-2023-3180#VulnChangeHistorySection
=> last update (2023-11-07) is the CPE update adding an upper bound to the
version
* but CVE lastmodified field does match the CPE update date (2023-11-07) :
https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-3180

At least, right now, the API output is "correct" (but does not match my
understanding of the doc). But, maybe it was "incorrect" (but matching the
doc) a few months ago?


> For example:
>> https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-6779
>> https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-6780
>> kirkstone has glibc 2.35 and nvd recently fixed these to >= 2.37 and
>> these ate still in patchmetrics.
>>
>> Email reports maybe use different (not-broken yet) NVD DB cache or make
>> full update instead of incremental?
>>
>> Peter
>>
>> -----Original Message-----
>> From: [email protected] <
>> [email protected]> On Behalf Of Richard Purdie via
>> lists.yoctoproject.org
>> Sent: Sunday, March 3, 2024 13:36
>> To: Simone Weiß <[email protected]>; Steve Sakoman <
>> [email protected]>; [email protected];
>> [email protected]
>> Subject: Re: [yocto-security] OE-core CVE metrics for master on Sun 03
>> Mar 2024 01:00:01 AM HST
>>
>> > On Sun, 2024-03-03 at 11:49 +0000, Simone Weiß wrote:
>> > > quick check: No news for any old issue, except cpio, which is
>> disputed
>> > > by the maintainer.
>> >
>> > Thanks, that is really useful to know!
>> >
>> > >
>> > > > Full list:  Found 41 unpatched CVEs
>> >
>> > I'm a bit puzzled/worried that our patch metrics page says 50 rather
>> than 41:
>> >
>> >
>> https://autobuilder.yocto.io/pub/non-release/patchmetrics/cve-status-master.txt
>> >
>> >:/
>> >
>> > Does anyone know why?
>> >
>> > Cheers,
>> >
>> > Richard
>>
>> 
>>
>>
>
> --
> Yoann Congal
> Smile ECS - Tech expert
>


-- 
Yoann Congal
Smile ECS - Tech expert
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#196566): 
https://lists.openembedded.org/g/openembedded-core/message/196566
Mute This Topic: https://lists.openembedded.org/mt/104701002/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to